Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

Ward AI's Analyzer

Upload a suspicious email, paste a link or drop a file. Ward tells you, in plain language, whether it looks like fraud and what to do.

What it does

  • Reads the email, link or file from the inside, code included. It never runs it and never visits its links.
  • Runs its technical checks and gives one of four verdicts, with the reasons and the steps to take.
  • Works in three tabs: Email, Link and File.
From the input to the verdict: an email, a link or a file goes through the checks, Ward AI can raise the result but never lower it, and one of four verdicts comes out.EmailLinkFileChecks, reading from the inside and never runningDomainAgeLookalikesTypeSignalsContentWard AI can raise the verdict, never lower itDangerousSuspiciousInconclusiveLooks legitimate

What it never does

  • Visit a link. It reads the address and checks the domain in DNS and in the registry (RDAP) and in Google Web Risk, without the query string or fragment. Shorteners are flagged, never expanded.
  • Run or save a file. It's read in memory only, under strict size, time and decompression limits, and then discarded.
  • Keep the email you upload. Only a cleaned-up copy of its text is stored, encrypted, for 7 days.
  • Say something is safe. The mildest verdict, “Looks legitimate”, only means no warning signs were found.
  • Touch your mailbox or your systems. It doesn't delete, block or report: that's up to you.

The three types

Email
Upload the original .eml or paste its source. Up to 4 MB.
Link
Paste an address (http, https or a bare domain). It's analyzed without visiting it. Query parameters are never stored.
File
Drop a file up to 4 MB. Ward detects its real type. The analysis stops after 10 seconds, or past 50 MB decompressed, 200 entries or 2 levels of ZIP inside ZIP. The file itself is never kept.

Getting the original email

For the Email tab, Ward needs the original message with all its headers: the proof of who sent it is there. These are the steps for each program, the same ones the “How do I get the email?” button shows.

Gmail

Download the file

  1. Open the email in Gmail on a computer.
  2. Click ⋮ (More) at the top right of the message.
  3. Choose “Download message”. Your browser saves an .eml file.
  4. In Ward, go to “Upload a file” and choose that .eml file.

Copy the source

  1. Open the email in Gmail on a computer.
  2. Click ⋮ (More) at the top right of the message and choose “Show original”.
  3. A new tab opens with the full source. Click “Copy to clipboard”, or select everything and copy it.
  4. In Ward, go to “Paste the source” and paste it into the box. The headers at the top must be included.

Gmail app on a phone

The Gmail app on a phone can't show or save the original email. Open the same email in Gmail from a computer and follow the steps above.

Outlook

Outlook on the web

  1. Open the email in Outlook on the web (outlook.com or outlook.office.com), on a computer.
  2. Click ⋯ (More actions) at the top of the message.
  3. Choose “View”, then “View message source”. A window opens with the full source.
  4. Select all the text and copy it (Ctrl+A then Ctrl+C on Windows, ⌘A then ⌘C on a Mac).
  5. In Ward, go to “Paste the source” and paste it into the box. The headers at the top must be included.

New Outlook for Windows

  1. Open the email.
  2. Click ⋯ (More actions) and choose “Save as”.
  3. Pick the .eml file type and save it.
  4. In Ward, go to “Upload a file” and choose that .eml file.

If you don't see “Save as”, open the same email in Outlook on the web and follow those steps instead.

Classic Outlook for Windows

  1. Classic Outlook can only save emails as .msg, and Ward can't read those. Open your browser and sign in to Outlook on the web with the same account.
  2. Find the same email there and follow the steps for “Outlook on the web”.

Outlook for Mac

  1. Select the email in the list.
  2. Drag it onto your desktop. Outlook saves it as an .eml file.
  3. In Ward, go to “Upload a file” and choose that .eml file.

Apple Mail

Mail on a Mac: save the file

  1. Select the email in Mail.
  2. Choose File, then “Save As…”.
  3. In the “Format” menu choose “Raw Message Source”, and save. The file ends in .eml.
  4. In Ward, go to “Upload a file” and choose that .eml file.

Mail on a Mac: copy the source

  1. Select the email in Mail.
  2. Choose View, then Message, then “Raw Source”. A window opens with the full source.
  3. Select all the text and copy it (Ctrl+A then Ctrl+C on Windows, ⌘A then ⌘C on a Mac).
  4. In Ward, go to “Paste the source” and paste it into the box. The headers at the top must be included.

Mail on iPhone or iPad

Mail on iPhone and iPad can't show or save the original email. Open the same email in Mail on a Mac, or sign in to its webmail (Gmail or Outlook on the web) from a computer, and follow those steps.

Any other program: anything that can save a message as .eml works, for example Thunderbird with File, then Save As.

  • Outlook .msg files aren't accepted. Save the email as .eml or paste its source.
  • Up to 4 MB per email, whether it's a file or pasted text.
  • A normal forward loses the original headers and the analysis comes out partial. Forward it as an attachment instead.

The four verdicts

Ward never says something is safe. When in doubt, it prefers “Suspicious” to “Looks legitimate”.

Dangerous
There's evidence of an attack: a link Google marks as dangerous, known malware, an executable or disk image, a macro that runs by itself and downloads something, a PDF or shortcut that runs code on opening, or a lookalike of your company asking for a password or a payment.Don't click, open or reply. Delete it or quarantine it. If someone already gave a password or opened a file, use “Did you already click?” below. Ward also warns the owners and administrators.
Suspicious
Warning signs without firm evidence: a shortener, a domain registered less than 30 days ago, a password-protected archive, a macro that runs by itself, scrambled code or a misleading double extension.Don't click or open anything until the sender confirms it through another channel, such as a phone call.
Inconclusive
Not enough to decide: the email's original headers are missing, the file can't be read or is encrypted, or the analysis ran out of budget.Don't trust it yet. For an email, upload the .eml file. For a file, ask the sender for another format.
Looks legitimate
The checks see nothing risky and, if Ward AI was used, it saw no fraud patterns.It isn't a guarantee. Don't share passwords or codes, and check any unusual request.

What Ward looks at

The analysis page lists what Ward found, the reasons and what to do. Links are always shown disabled (hxxps://example[.]com), so nobody clicks one by mistake.

In an email

Authentication
Whether the sender passed SPF, DKIM and DMARC. Ward trusts only the result written by your mail server or a large provider.
Sender
Whether it imitates your company or a known brand, and whether the display name matches the address.
Domains
Whether the domains exist and when they were registered. Under 30 days is a strong signal.
Links
Up to 20 per email: disguised text, bare IP addresses, lookalike characters, shorteners and plain http. Each one is also checked with Google Web Risk.
Attachments
Up to 20, with the same file analysis as the File tab.
Content
The cleaned-up text: urgency, sign-in requests, changes of bank details, gift cards. Text that tries to instruct automated reviewers is itself a warning sign.

In a link

Domain
Who really owns the address. Tricks like paypal.com.evil.top, IP addresses, odd ports and @ in the address are flagged.
Lookalikes
Similarity to your domains or to known brands, plus letters that look alike (rn for m).
Age
Registration age: under 30 days is a strong signal. An unknown age is shown as unknown, never as old.
Certificates
The first certificate seen for the host in Certificate Transparency. A brand-new one is a signal.
Reputation
Google Web Risk when available. Shorteners are flagged and never expanded.

In a file

Real type
The file's real type against its extension, double extensions and right-to-left tricks in the name.
Dangerous kinds
Executables, shortcuts and disk images, Office macros, remote templates and embedded objects.
PDF and archives
Actions that run on opening, JavaScript, password-protected ZIPs and executables inside a ZIP.
HTML, SVG, images
Forms that send data elsewhere, password fields and scripts. QR codes are read, and their link is analyzed as a link.
Code inside
Ward reads the code as plain text and never runs it: VBA macros, JavaScript in PDFs, scripts in HTML and SVG, the command line of .lnk shortcuts and the file names inside ISO images. It looks for code that runs by itself, downloads, hides addresses or sends passwords elsewhere.
Limits
If the time or decompression limits are hit, Ward stops and records that the file looks built to exhaust resources.

Did you already click?

On a dangerous or suspicious analysis, mark what happened: you clicked the link, entered a password, opened the file, enabled macros, paid or changed an IBAN, or sent data. Ward shows the steps in order right away, even without AI. For payments, call the bank first on a number you already trust. Ward never says the problem is solved; the marks are kept with the analysis for the weekly summary.

The role of Ward AI

  • If your plan's monthly limit allows it, Ward AI explains the result in plain words. It can raise the verdict, never lower it.
  • It reads a summary of the signals and, in emails, the cleaned-up text (up to 6,000 characters, without link parameters). Never the file, the full address or the email addresses.
  • For files with code, it reads trimmed fragments (up to 2,000 characters) as hostile data, never as instructions. Ward keeps up to 1,500 characters of them, encrypted.
  • Past the monthly limit, the analysis still runs with the checks only, labelled “Basic analysis”.
The Analyzer doesn't use your organization's Ward AI quota: its only limit is the monthly analyses of your plan, and even with the quota used up, every analysis within that limit gets its explanation. The panel “Ask Ward AI about this analysis”, on the analysis page, does spend the quota: it opens with that analysis as context. How Ward AI works.

Campaigns and alerts

  • If two or more suspicious or dangerous analyses from the last 7 days share a sender, a link domain, a file fingerprint or a subject, Ward groups them into a campaign.
  • A dangerous analysis triggers an email to the owners and administrators, and to the shared addresses confirmed in Alerts. One alert per campaign, with no clickable links.

When the verdict is wrong

On the analysis page, choose “The verdict is wrong”, say what it should have been and, if you want, add a short note. Don't paste the email or the file. Ward uses it to improve its checks, and the verdict you see doesn't change.

Who can use it, and how much

  • Owners, administrators and members can run analyses. Viewers can read the results but not upload.
  • It needs an active plan.
  • Essential includes 50 analyses a month and Professional 400 (emails, links or files). The count is per organization, restarts each month and shows in Analyzer and in Billing.
  • Past the monthly limit nothing is blocked: analyses still run with the checks only, labelled “Basic analysis”.
  • There's also a cap of 30 analyses every 24 hours per organization.
  • Only owners, administrators and the person who ran an analysis can see who ran it.

What Ward keeps

  • The email file and its attachments: never. Of an attachment, only its name, type, size and fingerprint.
  • Links: the normalized address without parameters or fragment, the registrable domain and the signals.
  • Files: never the contents. Only the shortened name, real type, size, SHA-256 fingerprint and the behaviors found, never the code.
  • Fragments of suspicious code, trimmed and encrypted, up to 1,500 characters: deleted 7 days after the analysis.
  • The cleaned-up text of the email body, encrypted: deleted 7 days after the analysis.
  • The rest (verdict, findings, links shown disabled, “Did you already click?” marks): 395 days, then deleted.
A summary of the signals, and the cleaned-up text when there is any, goes to OpenRouter, our AI sub-processor, only when Ward AI reads it. Link addresses, without query strings, go to Google Web Risk. An email or file name can contain other people's personal data, so tell your team before they upload one. Privacy Policy.